GnuTLS 'gnutls_handshake()' Function Remote Denial Of Service Vulnerability
BID:30713
Info
GnuTLS 'gnutls_handshake()' Function Remote Denial Of Service Vulnerability
| Bugtraq ID: | 30713 |
| Class: | Design Error |
| CVE: |
CVE-2008-2377 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2008 12:00AM |
| Updated: | Aug 27 2008 05:04PM |
| Credit: | Tomas Mraz |
| Vulnerable: |
GNU GnuTLS 2.4 GNU GnuTLS 2.2.5 GNU GnuTLS 2.2.4 GNU GnuTLS 2.2.3 GNU GnuTLS 2.2.2 GNU GnuTLS 2.2.1 GNU GnuTLS 2.2 GNU GnuTLS 2.0 |
| Not Vulnerable: |
GNU GnuTLS 2.4.1 |
Discussion
GnuTLS 'gnutls_handshake()' Function Remote Denial Of Service Vulnerability
GnuTLS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the computer, denying access to legitimate users.
Versions prior to GnuTLS 2.4.1 are vulnerable.
GnuTLS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the computer, denying access to legitimate users.
Versions prior to GnuTLS 2.4.1 are vulnerable.
Exploit / POC
GnuTLS 'gnutls_handshake()' Function Remote Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GnuTLS 'gnutls_handshake()' Function Remote Denial Of Service Vulnerability
Solution:
The vendor has released a fix to address this issue. Please see the references for more information.
GNU GnuTLS 2.0
GNU GnuTLS 2.2
GNU GnuTLS 2.2.1
GNU GnuTLS 2.2.2
GNU GnuTLS 2.2.3
GNU GnuTLS 2.2.4
GNU GnuTLS 2.2.5
GNU GnuTLS 2.4
Solution:
The vendor has released a fix to address this issue. Please see the references for more information.
GNU GnuTLS 2.0
-
GNU gnutls-2.4.1.tar.bz2
ftp://ftp.gnutls.org/pub/gnutls/gnutls-2.4.1.tar.bz2
GNU GnuTLS 2.2
-
GNU gnutls-2.4.1.tar.bz2
ftp://ftp.gnutls.org/pub/gnutls/gnutls-2.4.1.tar.bz2
GNU GnuTLS 2.2.1
-
GNU gnutls-2.4.1.tar.bz2
ftp://ftp.gnutls.org/pub/gnutls/gnutls-2.4.1.tar.bz2
GNU GnuTLS 2.2.2
-
GNU gnutls-2.4.1.tar.bz2
ftp://ftp.gnutls.org/pub/gnutls/gnutls-2.4.1.tar.bz2
GNU GnuTLS 2.2.3
-
GNU gnutls-2.4.1.tar.bz2
ftp://ftp.gnutls.org/pub/gnutls/gnutls-2.4.1.tar.bz2
GNU GnuTLS 2.2.4
-
GNU gnutls-2.4.1.tar.bz2
ftp://ftp.gnutls.org/pub/gnutls/gnutls-2.4.1.tar.bz2
GNU GnuTLS 2.2.5
-
GNU gnutls-2.4.1.tar.bz2
ftp://ftp.gnutls.org/pub/gnutls/gnutls-2.4.1.tar.bz2
GNU GnuTLS 2.4
-
GNU gnutls-2.4.1.tar.bz2
ftp://ftp.gnutls.org/pub/gnutls/gnutls-2.4.1.tar.bz2
References
GnuTLS 'gnutls_handshake()' Function Remote Denial Of Service Vulnerability
References:
References:
- Details on the gnutls_handshake local crash problem [GNUTLS-SA-2008-2] (Simon Josefsson
josefsson.org>) - GnuTLS (GNU)
- GnuTLS 2.4.1 (Simon Josefsson
josefsson.org>)